[Ncsg-discuss] SCCI Criteria 4 - “domain name security threats”
Johan Helsingius
00001963cc94b85a-dmarc-request at LISTSERV.SYR.EDU
Thu Jun 18 21:07:31 EEST 2026
All,
In light of this clarification from Manju, I would be inclined to
approve the proposed wording change. If any of you disagree
strongly, please speak up.
Julf
On 18/06/2026 10:16 am, Manju wrote:
> Hi all,
>
> Thank you for the questions.
>
> Before answering them, please allow me to provide more context on what
> we're doing in the SCCI with the Continuous Improvement Program Pilot
> and what the criteria and indicators are for.
>
> The Continuous Improvement Program (CIP) is ICANN's evolution of its
> traditional Organizational Reviews, which previously assessed how well
> Supporting Organizations, Advisory Committees, and the Nominating
> Committee fulfilled their purpose, structure, and accountability.
>
> The CIP rests on five shared principles covering purpose, structural
> effectiveness, operational efficiency, accountability, and
> collaboration. Each CIP assessment cycle runs up to three years and
> moves through three phases:
>
> * Assessment and Prioritization (data collection and identifying
> improvement areas),
> * Improvements (implementing changes), and
> * Reporting (publishing results for public comment).
>
> As the body in GNSO that's responsible for continuous improvement, SCCI
> has been following the CIP framework and principles to develop the
> criteria and indicators for future assessment and improvements. You can
> find the full set of criteria and indicators here: https://
> docs.google.com/document/d/1UoqrIjNArJFztNZ1Z9htTHCEIhJvIf2PNGLXgE_5HC0/
> edit?tab=t.0#heading=h.49smw22t8kla <https://docs.google.com/document/
> d/1UoqrIjNArJFztNZ1Z9htTHCEIhJvIf2PNGLXgE_5HC0/edit?
> tab=t.0#heading=h.49smw22t8kla>
>
> *Note: Please refrain from commenting on the Google Doc as we're
> currently only allowing the SCCI members to comment.*
> *
> *
> In short, we are now developing criteria and indicators for future data
> collection. And after collecting the data, we will assess it against the
> indicators and criteria, evaluating whether there is room for improvement.
>
> What you were asked to review was one of the indicators, and as it is a
> data point where we will be collecting data to assess against, we in
> SCCI decided to word it open-ended enough to allow the ease of data
> collection, while preventing scope creep by adding wording such as 'in
> scope for GNSO'.
>
> If you're interested in knowing more, I'd encourage you to listen to the
> recordings of our ICANN86 session, where we discussed this particular
> item in depth: https://icann86.sched.com/event/2NQMw/gnso-scci-work-
> session <https://icann86.sched.com/event/2NQMw/gnso-scci-work-session>
>
> Hope this helps.
>
> Best,
> Manju
>
> On Thu, Jun 18, 2026 at 3:34 PM Tapani Tarvainen <00001e7f5908374c-
> dmarc-request at listserv.syr.edu <mailto:00001e7f5908374c-dmarc-
> request at listserv.syr.edu>> wrote:
>
> Dear Manju,
>
> Thank you for the explanation. Looking at the proposed text again
> it makes sense. But the language is a bit ambiguous:
>
> > Indicator 1: The GNSO has demonstrated meaningful activity
> towards
> > mitigating DNS Abuse and security threats
> relating to
> > domain names that are in scope for the GNSO.
>
> Specifically, it's not clear if the qualification "that are in scope..."
> applies also to DNS Abuse and not only to security threats.
>
> I'm not sure this matters here, but perhaps it would be worth
> thinking a moment if it could be clarified without making the
> text too cumbersome.
>
> Tapani
>
>
> On Jun 17 15:02, Manju (000020eb0920d952-dmarc-
> request at LISTSERV.SYR.EDU <mailto:000020eb0920d952-dmarc-
> request at LISTSERV.SYR.EDU>) wrote:
> >
> > Hi all,
> >
> > Thank you very much for the discussion.
> > As mentioned by Julf, I'm the chair of SCCI and have to maintain
> neutrality
> > when it comes to the discussion of substance. However, I believe I'm
> > allowed to provide some context and clarification on this issue.
> >
> > The change from domain name security threat to DNS Abuse was
> actually an
> > effort of the SCCI to tighten the scope, not the contrary. The
> general
> > agreement within the SCCI was that "domain name security threat"
> can be
> > interpreted to have a broader remit that is beyond GNSO's mission and
> > scope, which prompted the change to 'DNS Abuse' as narrowly
> defined in the
> > contract.
> >
> > One of the examples that can be understood as 'combating domain name
> > security threat', as shared during our SCCI working session in
> Seville, is
> > the Internationalized Domain Names PDP, which regulates the variant
> > management of IDNs. By this example, it should be clear that
> domain name
> > security threat actually has a broader scope than DNS abuse, the
> latter of
> > which is narrowly defined and codified in contract.
> >
> > Hope this helps.
> >
> > Best,
> > Manju
> >
> > On Tue, Jun 16, 2026 at 8:36 PM farzaneh badii <
> > 00001deb507b73c5-dmarc-request at listserv.syr.edu
> <mailto:00001deb507b73c5-dmarc-request at listserv.syr.edu>> wrote:
> >
> > > Hi Julf
> > >
> > > I agree and we tried really hard in our public comments to
> mention the
> > > security threat and not frame it as DNS abuse, but the CPH and
> others were
> > > really keen on adding DNS abuse at the time. Maybe we can
> clarify that DNS
> > > abuse as narrowly defined in RAAs.
> > >
> > >
> > >
> > > Farzaneh
> > >
> > >
> > > On Tue, Jun 16, 2026 at 10:22 AM 鄭嘉逸 Chia I Cheng <
> > > 00001edb87ceea84-dmarc-request at listserv.syr.edu
> <mailto:00001edb87ceea84-dmarc-request at listserv.syr.edu>> wrote:
> > >
> > >>
> > >> Hi all,
> > >>
> > >> I'm broadly aligned with the direction of the discussion, but
> I think
> > >> it's worth pausing to consider why this proposed change is
> being raised
> > >> within the SCCI framework specifically — that context seems
> important to
> > >> how we shape our response.
> > >>
> > >> On the substantive question: is excluding "DNS Abuse"
> altogether actually
> > >> to our advantage? If the term can be held to a narrow,
> operationally
> > >> precise definition — one explicitly grounded in user rights
> and human
> > >> rights principles — we may end up with more meaningful control
> over how it
> > >> is applied than a rejection would give us.
> > >> Best,
> > >>
> > >> Chia-I
> > >>
> > >> *寄件者: *NCSG-Discuss <NCSG-DISCUSS at LISTSERV.SYR.EDU
> <mailto:NCSG-DISCUSS at LISTSERV.SYR.EDU>> 代表 NPC SVG <
> > >> 0000220936dcebb1-dmarc-request at LISTSERV.SYR.EDU
> <mailto:0000220936dcebb1-dmarc-request at LISTSERV.SYR.EDU>>
> > >> *日期: *星期二, 2026年6月16日 清晨6:12
> > >> *收件者: *NCSG-DISCUSS at LISTSERV.SYR.EDU <mailto:NCSG-
> DISCUSS at LISTSERV.SYR.EDU> <NCSG-DISCUSS at LISTSERV.SYR.EDU
> <mailto:NCSG-DISCUSS at LISTSERV.SYR.EDU>>
> > >> *主旨: *Re: SCCI Criteria 4 - “domain name security threats”
> > >>
> > >> Like Abbas and Julf , I also believe the use of the term DNS abuse
> > >> broadens the indicator into an area unsuitable for the GNSO
> council for
> > >> reasons described below.
> > >>
> > >> RD
> > >>
> > >> On Mon, Jun 15, 2026, 3:08 PM <
> > >> 0000222a86a53d44-dmarc-request at listserv.syr.edu
> <mailto:0000222a86a53d44-dmarc-request at listserv.syr.edu>> wrote:
> > >>
> > >> Julf, I agree with the analysis by Abbas. Explicitly Including
> “DNS
> > >> abuse” broadens the indicator into an area unsuitable for the
> GNSO Council
> > >> for the reasons he describes.
> > >>
> > >>
> > >>
> > >> In terms of a statement, we can perhaps relate something like
> “the ICANN
> > >> community has reached general consensus around a narrow set of
> DNS security
> > >> threats (phishing, malware, botnets, pharming, and spam as a
> delivery
> > >> mechanism). However, there has not been universal stakeholder
> consensus on
> > >> the broader conceptual definition of DNS Abuse or on where the
> boundary
> > >> lies between DNS abuse and content abuse. Therefore, since the
> term DNS
> > >> abuse” can mean different things to different stakeholders,
> even within the
> > >> narrow threats mentioned, by including "DNS abuse" as an
> indicator for
> > >> evaluating the performance of the GNSO council risks creating
> unclear, and
> > >> potentially unrealistic, expectations for achieving the stated
> criteria, to
> > >> say nothing of the opportunity for debate regarding whether or
> not the
> > >> criteria has been met.”
> > >>
> > >>
> > >>
> > >> I hope this helps.
> > >>
> > >>
> > >>
> > >> Ken
> > >>
> > >>
> > >>
> > >> *From:* NCSG-Discuss <NCSG-DISCUSS at LISTSERV.SYR.EDU
> <mailto:NCSG-DISCUSS at LISTSERV.SYR.EDU>> *On Behalf Of *Abbas
> > >> Sibai
> > >> *Sent:* Monday, June 15, 2026 9:33 AM
> > >> *To:* NCSG-DISCUSS at LISTSERV.SYR.EDU <mailto:NCSG-
> DISCUSS at LISTSERV.SYR.EDU>
> > >> *Subject:* Re: SCCI Criteria 4 - “domain name security threats”
> > >>
> > >>
> > >>
> > >> Hi Julf,
> > >>
> > >> Thanks for flagging this. As an individual member of the NCUC, I
> > >> completely share your concerns. Specifically inserting the
> term "DNS Abuse"
> > >> into the GNSO Continuous Improvement Program framework is a
> major red flag
> > >> that we definitely need to push back against during the
> upcoming call on
> > >> Wednesday, 1 July 2026.
> > >>
> > >> From our constituency’s perspective, my understanding is that
> there are
> > >> two distinct "cans of worms" this proposal opens up:
> > >>
> > >> - *Mission Creep and Content Regulation:* Broadening the
> text to
> > >> explicitly name "DNS Abuse" risks shifting the GNSO's focus
> from core
> > >> technical layer infrastructure toward content regulation.
> What I
> > >> understood is that the NCUC has a long-standing commitment to
> > >> fiercely protecting freedom of expression and digital
> rights. If the
> > >> indicators explicitly target "DNS Abuse" rather than
> strictly defined
> > >> security threats, it invites outside pressure on the GNSO
> to police website
> > >> content, a precedent that directly undermines our core
> mission and
> > >> human rights principles.
> > >> - *Disproportionality and Human Rights Impacts:* I also
> understood
> > >> that NCUC has consistently advocated that any policy
> intervention
> > >> addressing domain security must be narrow, proportionate,
> and strictly
> > >> scoped. Tying the evaluation of the GNSO's performance to
> broad and
> > >> subjective perceptions of "DNS Abuse" (especially via a
> survey indicator)
> > >> creates an incentive to pass sweeping, reactive policies.
> This places
> > >> innocent registrants at risk of collective or automated
> domain suspensions
> > >> without adequate due process or Human Rights Impact
> Assessments (HRIAs).
> > >>
> > >> The original text, focusing strictly on "mitigating domain
> name security
> > >> threats," keeps the evaluation grounded within the GNSO's
> technical and
> > >> contractual scope. The proposed revision unnecessarily
> complicates it and
> > >> opens the door to over-policing at the registry/registrar level.
> > >>
> > >> I fully support our leadership taking a strong stance against
> this text
> > >> on Wednesday. Please let me know if you need any assistance
> with drafting a
> > >> formal statement or if there are specific points you want
> supported during
> > >> the call.
> > >>
> > >>
> > >> Warm Regards,
> > >>
> > >> *Abbas Sibai*
> > >> *Policy & Advocacy Specialist*
> > >>
> > >> +9613824725
> > >>
> > >> *|*
> > >>
> > >> https://www.linkedin.com/in/abbas-sibai/ <https://
> www.linkedin.com/in/abbas-sibai/>
> > >>
> > >>
> > >>
> > >>
> > >>
> > >> On Mon, Jun 15, 2026 at 12:28 PM Johan Helsingius <
> > >> 00001963cc94b85a-dmarc-request at listserv.syr.edu
> <mailto:00001963cc94b85a-dmarc-request at listserv.syr.edu>> wrote:
> > >>
> > >> Hi all,
> > >>
> > >> I am the NCSG representative to the Standing Committee on
> Continuous
> > >> Improvement (SCCI) that is formulating the Continuous Improvement
> > >> Program framework. The SCCI is chaired by Manju, another
> NCSG:er, but
> > >> as chair she has to remain neutral.
> > >>
> > >> The work until now has been developing the Criteria and Indicators
> > >> that will be used to judge how well the GNSO processes are
> working.
> > >>
> > >> We have made good progress under the very capable leadership
> of Manju,
> > >> and most issues haven't been very controversial, but I want to
> flag
> > >> the current issue where we probably want to speak up against
> the current
> > >> proposal.
> > >>
> > >> The issue is Criteria 4, "The GNSO actively combats domain name
> > >> security threats", where there is a proposal to change the draft
> > >> text from:
> > >>
> > >> Indicator 1: The GNSO has demonstrated meaningful
> activity towards
> > >> mitigating domain name security threats.
> > >>
> > >> Indicator 2: 66% of surveyed respondents agree that the GNSO
> > >> combats domain name security threats.
> > >>
> > >> to:
> > >>
> > >> Indicator 1: The GNSO has demonstrated meaningful
> activity towards
> > >> mitigating DNS Abuse and security threats
> relating to
> > >> domain names that are in scope for the GNSO.
> > >>
> > >>
> > >> Indicator 2: 66% of surveyed respondents agree that the
> GNSO has
> > >> demonstrated meaningful activity towards
> mitigating
> > >> DNS Abuse and security threats relating to
> domain
> > >> names that are in scope for the GNSO.
> > >>
> > >> While we probably are OK with mitigating domain name security
> threats,
> > >> specifically mentioning DNS Abuse opens up some cans of worms.
> > >>
> > >> We will have a chance to present our views at the next SCCI
> call on
> > >> Wednesday, 1 July 2026, so I welcome your comments/opinions.
> > >>
> > >> Julf
> > >>
>
More information about the Ncsg-discuss
mailing list